CVE-2021-21148KEV · OVERDUE

Google Chromium V8 Heap Buffer Overflow Vulnerability

High · published February 9, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 97.3th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
20%
Percentile
97.3
In the wild
Confirmed
What it is

🚨 A crafted HTML page is your enemy here! This heap buffer overflow in Google Chrome's V8 engine can lead to serious heap corruption, making it a playground for attackers! ⚡ Think of it like a jigsaw puzzle with missing pieces: if someone sneaks in a wrong piece, it can mess up the whole picture, making it impossible to see the intended image. Similarly, this vulnerability can let an attacker insert malicious data that disrupts normal operations. An attacker could exploit this vulnerability to execute arbitrary code, leading to unauthorized access or even full control over your system. This is absolutely devastating since it could compromise sensitive information and personal data, putting you at risk!

Put simply

Think of it like a jigsaw puzzle with missing pieces: if someone sneaks in a wrong piece, it can mess up the whole picture, making it impossible to see the intended image. Similarly, this vulnerability can let an attacker insert malicious data that disrupts normal operations. The issue lies in how the V8 JavaScript engine processes memory. A heap buffer overflow occurs when data is written beyond the allocated memory buffer, which allows an attacker to manipulate the heap and potentially execute malicious code.

What to do

An attacker could exploit this vulnerability to execute arbitrary code, leading to unauthorized access or even full control over your system. This is absolutely devastating since it could compromise sensitive information and personal data, putting you at risk! Update Google Chrome to version 88.0.4324.150 or later to patch this vulnerability immediately. Regularly check for updates to prevent exploitation and enhance your overall security posture. 🛡️ You've got this! Stay vigilant and keep your browser updated to secure your digital world! 🔒

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.19968 · 97.3th percentile
Published
2021-02-09T15:30Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 09 FEB 15:30Z
    Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page
    cvelistv5